Описание
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
A flaw was found in the Consul Package. Affected versions of this package are vulnerable to information exposure via the /v1/internal/ui/nodes and /v1/internal/ui/services endpoints for cluster peering, which expose node and service information to unauthenticated attackers.
Отчет
The peering feature was introduced in Consul 1.13.0 as a beta feature. Red Hat products don't ship the affected versions of the Consul Package.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel8 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/cluster-curator-controller-rhel8 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/managedcluster-import-controller-rhel8 | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/topology-aware-lifecycle-manager-rhel8-operator | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-rhel9-operator | Not affected | ||
Red Hat Openshift Data Foundation 4 | odf4/odr-rhel8-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filt ...
Уязвимость инструмента настройки сервисов Consul и Consul Enterprise, связанная с раскрытием информации, позволяющая нарушителю получить доступ к потенциально конфиденциальной информации
7.5 High
CVSS3